Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-2xxc-73fv-36f7: llama-index vulnerable to arbitrary code execution

An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the exec parameter in PandasQueryEngine function.

ghsa
#git

llama-index vulnerable to arbitrary code execution

Critical severity GitHub Reviewed Published Aug 15, 2023 to the GitHub Advisory Database • Updated Aug 15, 2023

Related news

CVE-2023-39662: [Bug]: Prompt injection which will lead to RCE · Issue #7054 · jerryjliu/llama_index

An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the `exec` parameter in PandasQueryEngine function.